---
title: "Authentication"
canonical: "http://docs.symios.ai/integration/authentication"
lang: "en"
---

# Authentication

Integration credentials are company-scoped. Create and manage them in the Symios dashboard. Send both headers on every request to `https://api.symios.ai/v2/integration`.

## Credential lifecycle

- **Create** — returns `api_key` + `api_secret`. Store the secret securely; it is not shown again.
- **Rotate secret** — invalidates the previous secret immediately.
- **Disable / delete** — stops access for that credential.

## Making a request

### Authenticated request

**Endpoint**

```
GET /brands/list
```

**Headers**

| Name | Required | Description |
| --- | --- | --- |
| `X-Api-Key` | Yes | Public key identifier (e.g. sk_live_…). |
| `X-Api-Secret` | Yes | Secret shown once at create or rotate. |

**Query string parameters**

None

**Return**

```json
[
    {
        "id": 12,
        "name": "Acme"
    },
    {
        "id": 15,
        "name": "RivalCo"
    }
]
```

**Example (cURL)**

```bash
curl -sS "https://api.symios.ai/v2/integration/brands/list" \
  -H "X-Api-Key: sk_live_YOUR_KEY" \
  -H "X-Api-Secret: YOUR_SECRET"
```

## MCP connectors

LLM apps and developer tools can use the same credentials through the hosted [MCP server](http://docs.symios.ai/integration/mcp.md) (OAuth for ChatGPT/Claude.ai, or `X-Api-Key` / `X-Api-Secret` headers in Cursor and similar).
